Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. DevSecOps
  3. cicd-goat

cicd-goat

Apache-2.0Python1.2.7

A deliberately vulnerable CI/CD environment with 11 challenges to learn and practice CI/CD security.

GitHubGitHub
2.3k stars423 forks0 contributors

What is cicd-goat?

CI/CD Goat is a deliberately vulnerable CI/CD environment created for security education. It allows engineers and security practitioners to learn CI/CD security through a set of 11 hands-on challenges enacted against a real, full-blown CI/CD pipeline. The project helps users understand common attack vectors and the OWASP Top 10 CI/CD Security Risks in a safe, controlled setting.

Target Audience

Security engineers, DevOps practitioners, and developers who want to understand CI/CD security vulnerabilities and learn how to secure their pipelines. It's also suitable for security training programs and CTF enthusiasts.

Value Proposition

Developers choose CI/CD Goat because it provides a realistic, self-contained CI/CD environment with intentional vulnerabilities, enabling practical, hands-on learning without risking production systems. Its coverage of the OWASP Top 10 CI/CD risks and integration with a CTF framework make it a comprehensive educational tool.

Overview

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Use Cases

Best For

  • Learning CI/CD security through hands-on challenges
  • Practicing attack techniques in a safe, vulnerable environment
  • Understanding the OWASP Top 10 CI/CD Security Risks
  • Running security training workshops for DevOps teams
  • Preparing for security certifications with practical labs
  • Testing security tools against realistic CI/CD vulnerabilities

Not Ideal For

  • Teams deploying secure, production-ready CI/CD pipelines that need immediate hardening
  • Developers seeking a plug-and-play, secure CI/CD template for application projects
  • Environments with limited Docker resources or strict container quotas
  • Learners preferring passive, theoretical security training over hands-on challenges

Pros & Cons

Pros

Real-World CI/CD Tools

Integrates actual tools like Jenkins, GitLab, and Gitea in a Docker-based environment, providing a realistic simulation of interconnected CI/CD pipelines as shown in the architecture diagram.

OWASP Risk Coverage

Covers 8 out of 10 OWASP Top CI/CD Security Risks, with challenges focused on critical vulnerabilities like Poisoned Pipeline Execution (PPE) and Insufficient Flow Control Mechanisms.

Hands-On Challenge Design

Offers 11 themed challenges with Capture the Flag integration via CTFd, promoting active learning and problem-solving with flags to submit for progress tracking.

Easy Local Deployment

Can be set up without cloning the repository using simple Docker Compose commands for Linux, Mac, and Windows, as highlighted in the download instructions.

Cons

High Resource Consumption

Runs nine Docker containers simultaneously, including resource-heavy services like Jenkins and GitLab, which can strain systems with limited CPU or memory, as noted in the troubleshooting section.

Initial Configuration Delays

Containers may take up to 5 minutes to configure fully, and services like Gitea might show blank pages requiring refreshes, adding friction to the setup process.

Spoilers in Repository

The GitHub repository includes a 'solutions' directory and spoilers in files, which could accidentally reveal answers and undermine the self-directed learning experience if browsed.

Frequently Asked Questions

Quick Stats

Stars2,300
Forks423
Contributors0
Open Issues0
Last commit2 years ago
CreatedSince 2022

Tags

#security-training#jenkins#devops#cicd#hands-on-learning#infosec#gitlab#security#devsecops#docker#capture-the-flag#appsec#ctf#gitea#ci-cd-security

Built With

l
lighttpd
G
GitLab
D
Docker Compose
J
Jenkins
D
Docker

Included in

Security14.2kDevSecOps1.7k
Auto-fetched 7 hours ago

Related Projects

ZapZap

The ZAP by Checkmarx Core project

Stars15,765
Forks2,634
Last commit2 days ago
Kubernetes GoatKubernetes Goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

Stars5,775
Forks1,048
Last commit4 months ago
Bad SSLBad SSL

:lock: Memorable site for testing clients against bad SSL configs.

Stars3,047
Forks204
Last commit3 months ago
OWASP NodeGoatOWASP NodeGoat

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

Stars2,065
Forks2,851
Last commit2 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub